Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Hacked by Proxy: The Devious AnySign4PC Backdoor Campaign via South Korean Hacked Sites


South Korean hackers have exploited the AnySign4PC financial-security software via hacked sites to install backdoors without user prompts. The attacks are believed to be sponsored by a state agency and used spear-phishing tactics and zero-day flaws to spread malware.

  • Hackers exploited AnySign4PC financial-security software via hacked Korean sites to install backdoors without user prompts.
  • The attacks target visitors with vulnerable versions of the software, which were identified in June 2026.
  • Spear-phishing messages and zero-day flaws were used to spread malware, including remote command execution and file theft.
  • A state agency is believed to be behind the attacks, although it's unclear if both operations were carried out by the same entity.
  • Security experts recommend patching the software and hunting for suspicious behavior.



  • In a recent, concerning cyber attack, it was discovered that hackers have exploited the AnySign4PC financial-security software via hacked Korean sites to install backdoors without user prompts. According to South Korea's Internet and Security Agency (KISA), these compromised sites were used as watering holes to spread the malicious software, which is believed to be sponsored by a state agency.

    The attack targets visitors who run vulnerable versions of AnySign4PC software on their systems. This vulnerability was identified in June 2026, when KISA released a patch notice for affected versions. The Korea Internet & Security Agency warns that users should delete any installations of the affected version, as they are no longer secure without the latest fix.

    The attackers used spear-phishing messages disguised as resumes, recruitment approaches, investment material, and industry surveys to trick targets into visiting compromised sites. They then exploited a zero-day flaw in AnySign4PC software to deliver malicious payloads, which included remote command execution, file theft, internal reconnaissance, process injection, and additional payload delivery capabilities.

    The attackers also used privilege-escalation exploits, Mimikatz and other credential tools, Remote Desktop Protocol connections, and NLBrute to move through networks. The malware was identified as Struggle (maps to SIGNBT 3.0) or Brandoor (maps to COPPERHEDGE backdoor), with the latter being a particularly nasty variant that could read command-and-control information from the Windows registry.

    The attack campaign spans multiple sites and several organizations, including 15 legitimate websites used as watering holes. An investigation by AhnLab found overlap between this campaign and another ransomware intrusion known as Gunra in March 2026, which used the same vulnerability in financial-security software A (identified only as such).

    While it's unclear if both operations were carried out by the same entity or if there was collaboration, researchers at AhnLab noted that several pieces of evidence — including shared initial-access vulnerabilities, malware filenames and execution patterns, SSH key fingerprints, and network infrastructure — suggested a likely technical link between the two attacks.

    However, the reports do not establish whether the state-sponsored group behind this operation is Lazarus Group, which has been linked to previous AnySign4PC instances in South Korea. Despite this, the campaigns are believed to be sponsored by a state agency due to their sophistication and resources.

    Security experts recommend that users patch the software as soon as possible and hunt for suspicious behavior. ENKI Whitehat identified Type 1 backdoor deletions after copying malicious files into memory when running with self-protection enabled. Plainbit observed additional evidence destruction, including the use of SDelete and CCleaner to erase deleted files.

    KISA also noted that several compromised websites were connected to a single development and management company, which could be considered a possible supply-chain attack route.

    In summary, South Korean hackers have exploited the AnySign4PC financial-security software via hacked sites to install backdoors without user prompts. The attacks are believed to be sponsored by a state agency and used spear-phishing tactics and zero-day flaws to spread malware. Despite some overlap with a ransomware campaign, researchers do not believe that both operations were carried out by the same entity.

    South Korean hackers have exploited the AnySign4PC financial-security software via hacked sites to install backdoors without user prompts. The attacks are believed to be sponsored by a state agency and used spear-phishing tactics and zero-day flaws to spread malware.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Hacked-by-Proxy-The-Devious-AnySign4PC-Backdoor-Campaign-via-South-Korean-Hacked-Sites-ehn.shtml

  • https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html


  • Published: Thu Jul 30 07:29:14 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us